Summary | ZeroBOX

nc.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 May 23, 2023, 4:25 p.m. May 23, 2023, 4:27 p.m.
Size 35.7KB
Type PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
MD5 e0db1d3d47e312ef62e5b0c74dceafe5
SHA256 b3b207dfab2f429cc352ba125be32a0cae69fe4bf8563ab7d0128bba8c57a71c
CRC32 EA204BC5
ssdeep 768:SyMPVzXjrEX3wVdvEs/immkrYKoc4KYIoxU:DMPdrEGdvfamnnT4lIoG
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

WriteConsoleA

buffer: C
console_handle: 0x0000000b
1 1 0

WriteConsoleA

buffer: md line:
console_handle: 0x0000000b
1 1 0
Lionic Riskware.Win32.NetCat.1!c
MicroWorld-eScan Application.Generic.3167874
FireEye Generic.mg.e0db1d3d47e312ef
CAT-QuickHeal HackTool.Netcat.E1
ALYac Misc.HackTool.NetCat
Zillya Adware.BrowseFox.Win32.194079
K7AntiVirus Hacktool ( 000047b11 )
K7GW Hacktool ( 000047b11 )
Arcabit Application.Generic.D305682
Cyren W32/S-d35e0370!Eldorado
Symantec NetCat
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/RemoteAdmin.NetCat.AM potentially unsafe
Cynet Malicious (score: 100)
ClamAV Win.Trojan.Generic-9878071-0
Kaspersky not-a-virus:RemoteAdmin.Win32.NetCat.bnm
BitDefender Application.Generic.3167874
NANO-Antivirus Riskware.Win32.Netcat.ebbxjp
SUPERAntiSpyware Hack.Tool/Gen-RemoteAdmin
TACHYON Trojan/W32.Cometer.36528
Emsisoft Application.Generic.3167874 (B)
DrWeb Tool.Netcat.395
VIPRE Application.Generic.3167874
TrendMicro HKTL_NETCAT
McAfee-GW-Edition NetCat
Sophos NetCat (PUA)
Jiangmin RemoteAdmin.NetCat.s
Webroot Pua.Remoteadmin.Netcat
Antiy-AVL Trojan/Win32.SGeneric
Gridinsoft Risk.NetCat.sd!c
Microsoft HackTool:Win32/NetCat
ViRobot NetTool.NetCat.36528
ZoneAlarm not-a-virus:RemoteAdmin.Win32.NetCat.bnm
GData Application.Generic.3167874
Google Detected
AhnLab-V3 HackTool/Win.Netcat.C5350697
McAfee NetCat
MAX malware (ai score=99)
Cylance unsafe
TrendMicro-HouseCall HKTL_NETCAT
Rising Hacktool.NetCat!8.7CA (CLOUD)
Yandex Riskware.RemoteAdmin!I48oIyZSh24
Ikarus PUA.Tool
MaxSecure Trojan.Malware.4320.susgen
Fortinet Riskware/NetCat
DeepInstinct MALICIOUS
CrowdStrike win/grayware_confidence_100% (W)